View Cart
0 Items | Total: US$0.00
Welcome,      Register

You are here

asa

SEC0134 - SSL VPN AnyConnect Secure Mobility SCEP Proxy (Part 1)

The video shows you how to configure SCEP proxy on Cisco AnyConnect Secure Mobility to help VPN clients remotely obtain an identity certificate without allowing client to communicate directly to an internal Certificate Authority (CA) server. We will also show you how to solve the problem of how to select a correct certificate for VPN authentication when VPN client possesses multiple identity certificate using Certificate Matching feature. A basic working knowledge of certificate and SCEP is recommended before viewing this video.
Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0133 - SSL VPN AnyConnect Secure Mobility OnConnect Script

The video shows you how you can have Cisco AnyConnect Secure Mobility VPN to perform client-side script execution at both VPN connect and disconnect. This can be an alternative solution to Start-Before-Logon when used specifically for Windows logon script, which is what we will be demonstrating in this lab. At the end, we will also discuss caveats when using this technique.
Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0148 - ASA CX Passive Authentication with ISE (Part 2)

The video provide a method to enhance reliability of Cisco ASA CX Passive Authentication by integrating Cisco ISE with CDA. You will see how the caveats inherent to CDA can be solved by using realtime user and IP information provided by 802.1x identity-based authentication network. We will analyze RADIUS packets being communicated between Cisco ISE and CDA to try to understand the underlying mechanism. Testing will be performed on both domain and non-domain devices, that have been onboarded through ISE, and this includes both wired and wireless.

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0148 - ASA CX Passive Authentication with ISE (Part 1)

The video provide a method to enhance reliability of Cisco ASA CX Passive Authentication by integrating Cisco ISE with CDA. You will see how the caveats inherent to CDA can be solved by using realtime user and IP information provided by 802.1x identity-based authentication network. We will analyze RADIUS packets being communicated between Cisco ISE and CDA to try to understand the underlying mechanism. Testing will be performed on both domain and non-domain devices, that have been onboarded through ISE, and this includes both wired and wireless.

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0147 - ASA CX Passive Authentication

The video shows you the second method of obtaining user identity on Cisco ASA CX using Passive Authentication. We will leverage the User-to-IP mapping information provided by CDA by configuring CX device as a consumer. Once the mapping information is available to CX, minor modification will be performed on the Identity Policy and you will see how users are saved from having to enter their credentials as we saw in the Active Authentication. We will also discuss and demonstrate some caveats to this method towards the end of the lab.

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0146 - ASA CX Context Directory Agent Installation

The video walks you through an installation of Cisco Context Directory Agent (CDA) server. We will start by prepping a non-domain admin service account for CDA to use to contact Windows Active Directory. We will then step through a virtual machine creation, software installation and patching. We will also spend some time on the CDA web interface. By the end of the lab, we will be able to have CDA monitor user AD login activities and create user-to-IP mapping information that we will leverage in the future videos. 

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0132 - SSL VPN AnyConnect Secure Mobility Miscellaneous Features (Part 2)

The video takes you through some miscellaneous features on Cisco AnyConnect Secure Mobility. We will look through the Client Profile editor, specifically Preference Part 1 and 2, enable or disable each of the features expalin the effect they have on the VPN behavior. Below are a list of features that we will explore in this video.
Rating: 
0
No votes yet
Difficulty Level: 
3

SEC0132 - SSL VPN AnyConnect Secure Mobility Miscellaneous Features (Part 1)

The video takes you through some miscellaneous features on Cisco AnyConnect Secure Mobility. We will look through the Client Profile editor, specifically Preference Part 1 and 2, enable or disable each of the features expalin the effect they have on the VPN behavior. Below are a list of features that we will explore in this video.
Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0131 - SSL VPN AnyConnect Secure Mobility Start Before Logon

The video shows you how to provide network connectivity to Windows computers before user logon with Start-Before-Logon feature on Cisco AnyConnect Secure Mobility VPN. The feature provides a vehicle for the computer to contact Active Directory servers, for example, to authenticate the first-time login user without local account cache or to perform login script execution. Here we will use login script with drive mapping as part of our demonstration.
Rating: 
4
Average: 4 (1 vote)
Difficulty Level: 
0

SEC0145 - ASA CX Active Authentication (Part 2)

The video shows you the first method of obtaining user identity on Cisco ASA CX using Active Authentication. We will integrate CX with Windows Active Directory to perform user authentication as well as user group query. We will redo our access policies from the previous lab and replace the source IP subnet with AD user group. This would be our first step towards identity-based access policies and free ourselves from the use of just IP addresses. 

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

Pages

Subscribe to RSS - asa